Joyal

Privacy Policy

Last updated: July 2026


This Privacy Policy explains how Joyal ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our loyalty platform at joyal.co and any associated business-branded pages. We are committed to handling your data in accordance with the General Data Protection Regulation (GDPR) and applicable Irish and EU data protection law.

If you have any questions about this policy or how we handle your data, contact us at info@joyal.co.

1. WHO WE ARE

Joyal is a loyalty platform that enables local businesses to run digital loyalty programmes for their customers. Depending on your relationship with us, you may be a:

  • Customer: a member of a business's loyalty programme
  • Business Owner: a business that uses Joyal to manage their loyalty programme
  • Staff Member: an employee or team member of a business on Joyal
  • Affiliate: a referral partner of Joyal

This policy applies to all of the above.


2. WHAT DATA WE COLLECT

Depending on how you use Joyal, we may collect the following personal data:

Account & Identity

  • Full name
  • Email address
  • Phone number (optional)

Loyalty & Transaction Data

  • Points balance and transaction history
  • Rewards claimed and redeemed
  • Member number assigned to you
  • Visit history and activity timestamps

Business Data (Business Owners)

  • Business name, logo, branding assets
  • Billing and subscription information (handled via Stripe)
  • Staff invitation records

Communications

  • Email notification preferences
  • Push notification preferences and tokens
  • Unsubscribe records

Technical & Device Data

  • IP address (used for rate limiting and security)
  • User agent string (browser/device type)
  • Authentication session tokens

Location Data (Staff & Owner Accounts)

  • Approximate GPS position (latitude, longitude, and accuracy) of the staff device at the moment a scan, points adjustment, or reward redemption is processed
  • The registered business location the transaction was matched to
  • Location is captured only at the moment of these actions - staff devices are never tracked in the background.
  • We never access the location of Customer devices; the location recorded against a Customer's transaction comes from the staff device that processed it.

We do not collect payment card details directly. All payment processing is handled securely by Stripe.


3. HOW WE USE YOUR DATA

a) To provide the service (Lawful basis: Contract)

  • Create and manage your account
  • Track and display your loyalty points and transaction history
  • Process reward claims and redemptions
  • Allow staff to look up and manage customer accounts

b) To communicate with you about your account (Lawful basis: Contract / Legitimate Interest)

  • Send transactional emails (e.g. password reset, account signup confirmation, points awarded)
  • Send push notifications relating to your loyalty account activity (new rewards, reminders)

c) To send updates and news from a business you are a member of (Lawful basis: Consent)

  • If you opted in at signup, we may send you announcements, promotions, or news from the specific business whose loyalty programme you joined
  • You can withdraw this consent at any time by clicking the unsubscribe link in any such email or updating your preferences in your account

d) To operate and improve the platform (Lawful basis: Legitimate Interest)

  • Monitor platform performance and diagnose errors (via Sentry, server-side only)
  • Enforce rate limits and prevent abuse
  • Maintain audit logs of staff actions for security and accountability

e) To process payments (Lawful basis: Contract)

  • Business owner billing is handled by Stripe; we pass your billing details to Stripe for this purpose

f) To verify where transactions take place (Lawful basis: Legitimate Interest)

  • Attribute points and reward transactions to the business location where they occurred
  • Detect fraudulent, off-site, or otherwise suspicious transaction activity
  • Staff Members may decline the location permission on their device at any time; transactions will still complete and will simply be recorded without location information.

4. HOW LONG WE KEEP YOUR DATA

We keep your personal data only for as long as necessary for the purposes described above:

  • Active accounts: data is retained for as long as your account remains active
  • Inactive customer accounts: we aim to review and delete accounts with no activity after 3 years
  • Transaction history: retained for up to 7 years to meet financial record-keeping obligations
  • Location data: stored as part of transaction records and retained on the same basis as transaction history
  • Audit logs: retained for 2 years
  • Deleted accounts: when you delete your account, your personal details (name, email, phone) are removed; anonymised transaction records (with no link back to you) may be retained to preserve business reporting integrity

5. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. We use the following trusted third-party service providers ("sub-processors") who may process your data on our behalf:

All sub-processors are contractually bound to process your data only as instructed and in accordance with GDPR.

We may also disclose your data if required to do so by law, regulation, or a valid court order.



6. DATA SECURITY

We implement industry-standard technical and organisational measures to protect your personal data, including:

  • Encrypted connections (HTTPS/TLS) for all data in transit
  • Supabase row-level security (RLS) policies restricting data access to authorised users only
  • Authentication tokens stored securely with automatic expiry
  • Rate limiting on all sensitive API endpoints
  • Server-side error monitoring without personal data exposure

No system is completely secure, and we cannot guarantee absolute security. If you become aware of any suspected breach, please contact info@joyal.co immediately.

7. COOKIES

We use a minimal number of cookies. We do not use advertising cookies, tracking cookies, or third-party analytics cookies.


Session Cookie (Strictly Necessary)

  • Name: sb-[project-ref]-auth-token (set by Supabase Auth)
  • Purpose: Keeps you securely logged in while you use the platform. This cookie contains an encrypted authentication token and is required for the service to function.
  • Duration: Expires when you log out or after a period of inactivity (typically 1 hour for session tokens, up to 1 week with refresh).
  • Third-party: No - set by Joyal's own infrastructure via Supabase.

Because we only use strictly necessary cookies, we are not required to obtain your consent before setting them under the EU ePrivacy Directive. If you wish to remove all cookies, you can clear your browser's cookies at any time, though this will log you out of the platform.

We do not use Google Analytics, Facebook Pixel, or any other tracking or advertising cookies.

8. YOUR RIGHTS UNDER GDPR

As a data subject under GDPR, you have the following rights:

  • Right of Access - you can request a copy of the personal data we hold about you.
  • Right to Rectification - you can ask us to correct inaccurate or incomplete data.
  • Right to Erasure - you can request that we delete your personal data. You can also delete your own account directly from within the app; see Settings > Delete Account.
  • Right to Restriction of Processing - you can ask us to pause processing your data in certain circumstances.
  • Right to Data Portability - you can request your data in a structured, machine-readable format.
  • Right to Object - you can object to processing based on legitimate interest, or withdraw consent for marketing communications at any time.
  • Rights related to Automated Decision-Making - we do not make any solely automated decisions that produce legal or significant effects about you.

To exercise any of these rights, email info@joyal.co. We will respond within 30 days. We may need to verify your identity before processing requests.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Data Protection Commission (Ireland)

9. CHILDREN'S DATA

Our platform is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us at info@joyal.co and we will delete it promptly.


10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this document. We encourage you to review this policy periodically. Continued use of the platform after changes are posted constitutes your acceptance of the updated policy.


11. CONTACT US

For any privacy-related questions, data access requests, or complaints:

Email: info@joyal.co

Website: https://joyal.co


Joyal

Ireland